Backdoored PyTorch Lightning package drops credential stealer
2026-05-04T19:23:36Z•763923704c7244bcab31c4148273f7903f0e64124e2d3ec81f420f256d61c901
PyPIandroid-malwareauth-bypassbackup-failureconsentfixcopy-failcpanelcredential-stealerdata-breachdigicertfalse-positiveinstructurelinuxmicrosoftmoveitoauth-abusepytorch-lightningransomwareroot-exploitshinyhunterssource-code-leaksupply-chaintelegram
What happened
Multiple active threats and incidents reported: a backdoored PyTorch Lightning PyPI package was distributing a credential‑stealer targeting browsers, environment files and cloud credentials; Progress warned of a critical authentication‑bypass flaw in MOVEit Automation with urgent patching advised; the "Copy Fail" Linux vulnerability is being exploited in the wild to gain root; cPanel flaw CVE-2026-41940 is being mass‑exploited in "Sorry" ransomware attacks. Additional notable items include source‑code/data breaches at Trellix and Instructure (ShinyHunters claim), Microsoft April updates that破破
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 763923704c7244bcab31c4148273f7903f0e64124e2d3ec81f420f256d61c901
- Enrichment time
- 2026-05-04T19:23:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.